PRIVACY POLICY
Privacy Policy
We minimise data collection through product architecture and keep control of health data in the user's hands.
Effective date: 2 August 2026
1. Scope
This policy applies to the Aster iOS app and this support website. Aster is a personal health and lifestyle companion. It does not provide medical diagnosis, treatment, or emergency services.
2. Data Aster accesses
Aster reads read-only health data — such as steps, sleep, HRV, heart rate, activity, and recovery metrics — from Apple Health, Google Health, or other compatible sources only after you actively connect and authorise them. Each data source is controlled separately by you on the system's or provider's own authorisation screen.
This website does not ask you to sign in and does not collect health data through forms. What you send to the support email is up to you.
3. On-device data flow for Google Health
Google OAuth tokens are stored only in the keychain of the user's iOS device. Authorisation, token refresh, and Google Health API requests go from the device directly to Google's official endpoints; responses are parsed and displayed on the device and never pass through any server owned or controlled by the Aster developer.
Aster's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. On-device storage and security
Health trends, meal records, and AI conversations are stored on the user's device with on-device encryption; the keys live in the iOS keychain. Google tokens are protected by a this-device-only keychain class. HealthKit personal health information is not synced to Aster's CloudKit container, and meal photos and image text are processed on the device by default.
5. Bring-your-own-key third-party AI (BYOK)
Aster works in a local, offline mode by default. You may also choose to configure Google Gemini, DeepSeek, Tongyi Qianwen, or another OpenAI-compatible AI service. API keys are stored only in your device's keychain.
An ordinary cloud question sends only the text you typed for that question plus a catalogue of available data types with no values attached. It does not automatically include steps, sleep, HRV, heart rate, past conversations, names, calendar titles, raw HealthKit samples, or your full health timeline.
When the model decides it needs health values to answer, Aster only generates a request. Only after you open the “choose what to send” screen, review the recipient and fields, select each item, and confirm, is the selected content sent directly to that third-party AI. The grant is bound to the current question and recipient and expires after one use. Data received by third parties is governed by their own privacy policies.
6. What we do not do
- We do not sell or rent your health data.
- We do not use health data for advertising or ad profiling.
- We do not use Google user data to train Aster or general-purpose AI models.
- We do not store Google OAuth tokens or Google Health data on Aster servers.
7. Retention, deletion, and revocation
On-device data is under your control. You can delete records, clear AI conversations, disconnect data sources, or uninstall the app. When you disconnect Google Health, Aster asks Google to revoke the grant directly from the device and deletes the token from the local keychain. See Delete Data and Revoke Access for the exact steps.
8. Policy updates and contact
If the way we handle data changes materially, we will update this page and its effective date, and where appropriate notify you in the app. For enquiries, complaints, or help with deletion, contact imakoshan@gmail.com.